Security and trust
Vulnerability Disclosure Policy
Thank you for helping EchoBay protect its users and services. If you believe you found a security issue, stay within these boundaries, stop after obtaining the minimum proof, and report it privately through the dedicated security mailbox.
Report a security issue privatelyTesting scope
This policy covers only the following public services operated by EchoBay:
echobay.clubapp.echobay.clubapi.echobay.clubdownloads.echobay.club
Testing boundaries
- Do not perform Denial-of-service attacks (DDoS/DoS), high-volume load testing, or other activity that harms availability.
- Do not use social engineering, phishing, impersonation, harassment, or deception against EchoBay users, staff, or suppliers.
- Do not establish persistence, install a backdoor, retain unauthorized access, or continue access after verification.
- Do not destroy or alter data, including deleting, writing, moving, or corrupting it.
- Do not access another user's data. If you see it accidentally, stop immediately and do not download, copy, retain, or share it.
How to report
Stop once you have confirmed the issue, retain only the minimum proof, and report it privately to security@echobay.club. Do not disclose it publicly or include unrelated personal data, credentials, or complete datasets.
- Identify the affected domain, path, feature, and the impact you observed.
- Provide the fewest safe reproduction steps. Redact sensitive values and include only the fragment needed to understand the issue.
- Include contact details you want us to use for follow-up.
Response targets
After the dedicated security mailbox receives a complete, actionable report, we aim to:
- Within 3 business days
- Acknowledge the report and provide a tracking status.
- Within 7 days
- Complete an initial severity classification and outline next steps.
- Immediate containment
- Prioritize isolation and emergency containment for serious active exploitation.